Cloud 101CircleEventsBlog
Master CSA’s Security, Trust, Assurance, and Risk program—download the STAR Prep Kit for essential tools to enhance your assurance!

Research Topic

Vulnerability Data

Global Security Database Working Group Charter
Global Security Database Working Group Charter

Download

Vulnerability Data
Given the increase in successful attacks against all forms of IT infrastructure it has become obvious that current efforts to track vulnerabilities using vulnerability identifiers has reached its limit. Identifiers need to be easily discovered, fast to assign,updatable, and publicly available. The number of vulnerabilities is growing faster than we are currently able to track them.

With the proliferation of open source usage in services and commercial software the requirements for vulnerability identifiers have changed. The need for increased scope of coverage, deeper reporting and information, and reduced latency are now requirements. Everyone in IT is building and consuming software in unique ways, there is no one single way in our modern infrastructure; any attempt at a one-size-fits-all is doomed to failure.

You can learn more about why this group was created in this blog from Cloud Security Alliance’s Founder and CEO, Jim Reavis.  

As an industry, we need to start talking about how to solve this problem. One way you can do this is by joining our working group at https://csaurl.org/gsd-signup. We also would like to encourage you to get the conversation started by sharing any questions or ideas you have for this project in the Global Security Database (GSD) Community on Circle

Related resources:

Vulnerability DataVulnerabilities

Related Resources

CSA Research crowd-sources the knowledge and expertise of security experts and helps address the challenges and needs they’ve experienced, or seen others experience, within the cybersecurity field. Each publication is vendor-neutral and follows the peer review process outlined in the CSA Research Lifecycle. We recommend getting started by reading the following documents.

Global Security Database Working Group Charter

Global Security Database Working Group Charter

The scope of this project is to identify and understand the problems around vulnerability discovery, reporting, publication, tracking, and classification. Using the same style of open source collaborative techniques that have worked to create the software ecosystem that we have today, the CSA is creating a community focused working group meant to replicate this success in the vulnerability identifier problem space. The project is not limited to vulnerabilities in the cloud as we are seeing the same problems and increase in attacks across all forms of IT infrastructure. The common design goal is for vulnerability identifiers to be easily discovered, fast to assign, updatable, and publicly available.

Webinars

Riding the OpenSource Security Rollercoaster
Riding the OpenSource Security Rollercoaster

February 16 | Online

Learn more

Risk Management in 2022: Take it Up a Notch
Risk Management in 2022: Take it Up a Notch

March 2 | Online

Learn more

Securing the Data and AI Landscape with DSPM and DDR
Securing the Data and AI Landscape with DSPM and DDR

October 3 | TBD

Learn more

Cyber Attacks: It's not if, It's when! Why aren't we prepared?
Cyber Attacks: It's not if, It's when! Why aren't we prepared?

October 10 | Online

Learn more

Blog Posts

A Vulnerability Management Crisis: The Issues with CVE
What is Offensive Security and Why is it So Challenging?
Predicting Monthly CVE Disclosure Trends for 2024: A Time Series (SARIMAX) Approach